(the /s is just on the "oh wait" part, not the whole post)
The hard part (and it truly is hard!) is convincing a few companies to do this. It risks user complaints in the short term, to solve a problem that may not be very acute for the largest companies (who can simply absorb these attacks).
(No I don’t expect any response but I am just leaving this thought for those who stumble on this thread in the future).
ISPs do this literally all the time. They sell services that do this.
not necessarily true
Shout out to Dutch ISP XS4ALL who was (is?) very very strict and active in this space.
Also, sounds illegal.
Step 2: Execute DDoS
Step 3: Prove to others you are responsible by using private key
It's not obvious what's the value of having the largest ineffective attack.
One gets you more money in the short term. The other one gets you more street cred - which gets you more money in the long term.